Endpoint Protection Policy is not Applied

Benoit LecoursSCCM, SCEP4 Comments

This post explains what to do when Endpoint Protection policy not applied Symptom The policy was applied to a specific collection and all members of the collection were failing to apply the policy Monitoring / Endpoint Protection Status / System Center 2012 R2 Endpoint Protection Status / Operational State 12 clients are failing to apply the custom policy. Clicking on the “Antimalware policy application failed” brings us to the list of machine. On the bottom, clicking on the “Antimalware Policy” tab shows the error : 0x80004005 – Failed to generate Antimalware policy file Let’s look at the EndpointProtectionAgent.log on one of the … Read More

Browsing Sites in Create Boundary Section won’t provide Multi-Domain Active Directory Sites

Nicolas PilonSCCM9 Comments

One of the fundamentals aspect of configuration manager is the boundary because you can’t manage anything without a boundary.  (Thanks to Torsten for pointing that it’s possible to manage client without a boundary).  There’s different types of boundary like, IP subnet, IP address range, IPv6 prefix and active directory site. The last one is the recommended method and it’s the easiest to manage. We recently migrate our infrastructure to SCCM 2012 and we have an issue during the boundary configuration. What happen if you have 2 domains with the same active directory site? No big deal, both will be detectable … Read More

Understanding the Reassign Distribution Point Process

Benoit LecoursSCCM, SQL5 Comments

Here’s a detailed post on the process of upgrad (RTM,SP1) / reassign distribution point from 2007 during your migration project. What really happens when you click on “Reassign Distribution Point” on ConfigMgr 2012 R2: ? How to track the progress ? The process is quite simple : 1. Removal of DP role in the 2007 site 2. Delete site system record in the 2007 site 3. Delete shared DP role in the 2012 site 4. Delete shared DP site system record in the 2012 site 5. Install a new site system in the 2012 site 6. Install a new DP role in … Read More

Is_Virtual_Machine in v_R_System is not showing Properly with a Virtual Machine under VMWare ESXI 5.1

Nicolas PilonSCCM, SQL2 Comments

There’s a new field in v_R_system view on SCCM 2012 SQL database named Is_Virtual_Machine. It is really easier when it’s time to target virtual machines with this field instead using manufacturer, model or v_GS_Virtual_Machine under SCCM 2007. Today, we were making a spot check in our data integrity when we found two manufacturers and models VMWare flagged as non-virtual machine. In the SCCM SQL database, the source for v_R_system view is System_DISC. The associate WMI class is SMS_R_System Server. From the MSDN website, the description of Is_Virtual_Machine in the WMI class is. 1 is a virtual machine and 0 is a physical machine. How … Read More

Set an HTTPS Distribution Point as a Source DP for Pull DP

Benoit LecoursSCCMLeave a Comment

I worked in an environment where all DP are set to communicate with HTTPS. When trying to add a DP as a pull DP source, you get this : Technet is specifying that “Only distribution points that support HTTP can be specified as a source distribution points when you use the Configuration Manager console” http://technet.microsoft.com/en-us/library/gg712321.aspx You can configure a pull-distribution point when you install the distribution point or after it is installed by editing the properties of the distribution point site system role. A distribution point that you configure as a pull-distribution point can transfer content to clients by HTTP … Read More

Configuration Manager 2012 Client Command List

Nicolas PilonSCCM32 Comments

I recently found in our infrastructure that a lot of new Windows Server 2012 Core Edition were installed for specific reason. This edition can cause some problems to administrators that are not aware of SCCM commands. Here is the list of actions that will be covered in this post: Configuration Manager client services and properties Configuration Manager agent scan trigger EndPoint Protection client installation and properties Logs directory There’s a lot of commands that can be execute but I will give you the minimum to remember. From ‘cmd’, type those commands for configuration manager. Configuration Manager Client Scan Trigger with … Read More

Software Update – Computer Part of a Maintenance Windows doesn’t Reboot

Benoit LecoursSCCM5 Comments

Scenario : You deploy Software Updates to a specific collection that has a maintenance window configured. The machine doesn’t reboot as required Troubleshooting : Check the Maintenance Windows properties The maintenance Windows is set to a 2h duration : Check the Deployment properties The first step is to make sure that your deployment allows reboot: My machine is a Windows 2012 (thus considered a server) and the option to suppress reboot is not selected. Check if there’s overlapping maintenance Windows Using the built-in report “Maintenance windows available to a specified client”, I can see that my maintenance Windows is applied … Read More

Security Update for Internet Explorer KB2964358

Benoit LecoursSCCMLeave a Comment

Microsoft has release a critical security update to fix the “famous” IE security vulnerability. Full details @ https://technet.microsoft.com/library/security/ms14-021 The good news for you as an SCCM admin is that it’s easy to deploy. Just make sure that your software update point successfully sync with Microsoft and you’ll find the update in your console. If it’s not listed, initiate a manual sync. Track the synchronization process in wsyncmgr.log Once completed you’ll see the update in the console : When the sync completes, add the update to your deployment package and deploy it to your devices.   Internet Explorer KB2964358

Error in Migration Job with SCCM 2012

Benoit LecoursSCCMLeave a Comment

During an SCCM Migration project, you may encounter this SCCM Migration Job error: “Object modified after Migration” SCCM Migration Job Error “No objects can be selected in this type of job, please select another type of migration job or check the data gathering jobs to make sure they are working” This error occurs because you’ve completed a migration job and you try to another one before the next data gather process. To fix this, simply wait for the next data gathering process (default 4h) or manually initiate it. Once completed, recreate your migration job and the error will no longer … Read More

Content Conversion not showing your Packages when reassign DP

Benoit LecoursSCCM1 Comment

Symptoms : SCCM Administrators tries to Upgrade/Reassign a distribution point in a migration project. The Content Conversion tab is displaying There are no items to show in this view If you complete the wizard, the DP gets upgraded/reassign but the content is not (obviously). This happens because the package assigned to this DP are not migrated to the 2012 hierarchy. Solution : Create a migration job targeting your packages before reassigning the DP Bonus note : You can refer to the Hosted Migrated Package column in order to see how many packages are link to this DP.